SlideShare a Scribd company logo
1 of 60
Kildow Consulting
Presenters
Kildow Consulting
 Business continuity and supply chain management consultant, advisor, trainer,
speaker, author
 More than 25 years partnering with widely diverse businesses and organizations to
develop and maintain continuity and resilience
 Fellow of the Business Continuity Institute (FBCI) 2002
 Certified Business Continuity Professional (CBCP), DRII 1998
 ISO 22301 Master
 ISO 28000 Lead Implementer/Lead Auditor
 Conduct ISO-28000 and ISO-22301 internal audits and reviews
 PECB Certified Trainer
 Author, A Supply Chain Management Guide to Business Continuity, 2011; in
Japanese「事業継続」のためのサプライチェーン・マネジメント
Betty A. Kildow
Kildow Consulting
• Founder & Principal Consultant @ Business As Usual (started 2006)
• MSc (Engineering) – TU Delft, the Netherlands - Honours
• 20+ years of consulting experience globally
• ISO 22301 Master – ISO 31000 Lead Risk Mgr – ISO 27001 Master
• CBCP, MBCI, ITIL Master, COBIT certified
• Regularly conducting ISO 27001 certification audits
• Consulted to 15 Central Banks and 100s of other Government
entities, SMEs and larger corporates across Australasia, Africa,
Europe and Latin America
Rinske Geerlings
Risk Consultant of the Year 2017 (RMIA)
Outstanding Security Consultant of the Year 2019 (OSPAs Finalist)
Kildow Consulting
• ISO 31000 Lead Risk Manager
• ISO 22301 Lead Implementer
• ISO 9001 Lead Implementer
• PECB Certified Trainer
• Worked with clients across industries to develop and review
their enterprise risk and business continuity management
frameworks.
Michael Kamau Kiiru
Senior Consultant at Sentinel Africa Consulting
Experienced risk manager and trainer specializing in enterprise
risk management, business continuity management
Photo
Kildow Consulting
Business Continuity & ISO 22301
Essential in Building a More
Resilient Organization
Kildow Consulting
What Is
Business
Continuity?
1,000,000 choices
• Timely, orderly continuation or rapid restoration
of delivery of the organization’s service or
product following a disruption of any magnitude.
• Includes strategies and plans developed from the
perspective of keeping the most critical functions
running while normal operations are restored.
• Capability of the organization to continue delivery
of products or services at acceptable predefined
levels following a disruptive incident. ISO 22301,
clause 3.3
Kildow Consulting
Here is Your First Quiz
What is the precise full official name of
ISO-22301 – with all correct punctuation?
Kildow Consulting
What is ISO 22301?
• Full name of the standard is: ISO 22301:2019 Societal security – Business continuity
management systems – Requirements.
• Billed as the world's first international standard for business continuity management
(BCM)
– Written by leading business continuity experts
– Provides the best framework for managing business continuity in an organization.
• An organization can become certified by an accredited certification body and will
therefore be able to prove its compliance to its customers, partners, owners and
other stakeholders.
• Any organization – large or small, for profit or non-profit, private or public can
implement the standard.
What is ISO 22301?
Kildow Consulting
ISO 22301 Standard
Specifies requirements for
BCMS management
Requirements (clauses) are
written using the imperative
verb “shall”
Integrate the PDCA (Plan, Do,
Check and Act) model
Auditable
Organization can obtain
certification against this
standard
Kildow Consulting
Why ISO-22301:2012 Had Me at Hello
Business Continuity Management System
– Includes the supply chain
– Requires top management involvement
– Globally accepted standard
– Sets requirements for a business continuity management
system
– Provides guidance on the implementation of a comprehensive
Business Continuity Program
– Provides solid evidence of business continuity competence
Published in May 2012 by the technical committee, ISO 22301:2012 is the first international standard
for management systems that help ensure business continuity. ISO 22301 is the premium standard
for business continuity, and certification demonstrates conformance to rigorous practices to prevent,
mitigate, respond to, and recover from disruptive incidents.
Kildow Consulting
Value of a
Business
Continuity
Management
System
Many stakeholders care about your business continuity capability;
some have a vested interest.
In extreme situations the success, even survival, of your
organization as it exists today may depend on its business
continuity capability.
The number of regulatory and legal requirements that include
having a business continuity program continue to increase in
number.
For public utilities there is an ethical requirement to protect the
interests of all customers.
Customers need and expect your products and services to be
available even when significant disruptions and disasters occur.
Developing, implementing, and maintaining a continuity program
that ensures the organization can continue operations even in the
face of disaster, thus avoiding damage to the company’s brand,
image, and reputation, and losses to the bottom line.
Kildow Consulting
Advantages of Business Continuity
Predictable and
effective
response to
crises
Protection of
people
Maintenance of
vital activities of
the organization
Better
understanding of
the organization
Mitigation of
Risks
Respect of the
interested
parties
Protection of the
reputation and
brand
Confidence of
clients
Competitive
advantage
Legal
compliance
Regulatory
compliance
Contract
compliance
Kildow Consulting
Definition: Establishment of policies and
continuous monitoring of their proper
implementation by members of the governing
body of an organization
• Adopt formal Business Continuity Policy
• Identify who has overall ownership
• Establish a central point of accountability,
oversight, and support
• Ensure proper monitoring to ensure
requirements are met - and follow-up as
necessary
• Assign roles and responsibilities
Kildow Consulting
Business Continuity’s Value
Beyond Business Continuity
• Gather information from across the
organization
• Gain an in-depth understanding of the big
picture
• Develop a greater understanding of
internal and external interdependencies
• Identify redundancies and opportunities for
efficiencies
Kildow Consulting
“You can't go
back and change
the beginning, but
you can start
where you are
and change the
ending.”
C.S.Lewis
COVID – Two Years and Counting
 Global
 Prolonged
 Impacted people, facilities, equipment, suppliers,
technology, infrastructure
 Required extraordinary levels of adaptability
 What seemed impossible was made possible
 Higher awareness of the need for business
continuity than ever before
 Unparalleled lessons for needed improvements to
our Business Continuity Programs
Kildow Consulting
Requirements for Successful Business Continuity
Enterprise-wide integrated involvement
Total collaboration among all risk-
related business units
Fully addressing a wide range of
internal and external operational risks
Strategies and plans that are flexible,
scalable
Kildow Consulting
Internal Partnering
Strategy and plan
development
• Give ownership to the
implementers
• Train and empower
IT/DR
• Collaborative DR and
BC exercises and tests
• IT is also a business
unit
One small step for
business continuity-
kind; one giant step
for a successful BCMS
• Adopt a shared
glossary of business
continuity terms and
acronyms that is used
across the
organization
Kildow Consulting
• Business Continuity Plans need to outline how
each individual plan coordinates, collaborates, and
communicates with other plans:
– Corporate-level Business Continuity Plan
– Department / Division Business Continuity
Plans at all locations
– Business Continuity Plans for strategic,
tactical and operational levels
– Disaster Recovery Plan
– Emergency Response Plan
– Other risk-related plans
• A change in one will likely require changes in
others
Kildow Consulting
Business
Continuity’s
Role in
Cybersecurity
and Vice
Versa
• It is a fact that BC, DR and Cybersecurity
activities often occupy separate silos
• Those barriers need to come down
• Business continuity does not prevent nor lead
the charge to recover from cyber attacks
• Business Continuity’s role is to ensure that the
organization can still function in spite of any
disruption, including of cyber attacks
Collaboration is the key to success. There is strength and power
in coming together to find answers to current and future
common challenges.
Kildow Consulting
Executive
sponsorship,
involvement, and
commitment
Focus on sustaining
operations essential
to the delivery of
products and
services
Clearly defined
ownership and
responsibility
Full communication
of the program
enterprise wide
Full coordination
and integration of all
risk-related
programs
Regular reviews
and audits and
updates
Comprehensive
training, exercising
and testing
Integrated into
culture and
operations
ISO-22301
Essentials for
Ongoing
Business
Continuity
Success
Kildow Consulting
Information Security & ISO 27001
Recent ISO 27001 developments &
Differences between Cyber Incident
Response Planning and ISMS
Kildow Consulting
Why ISMS?
Compliance (SOC, Sox, 3rd party)
Kildow Consulting
Kildow Consulting
Ransom payments…
IN PRINCIPLE ≠ IN PRACTICE
Kildow Consulting
ISO 27001 – What is it?
ISO/IEC 27001 (usually shortened to
“ISO 27001”) is an Information
Security Management System standard
written jointly by the International
Organization for Standardization (ISO)
and the International Electrotechnical
Commission (EC). This standard lays
out universal best practices for creating
and maintaining an information security management system (ISMS).
It helps organizations protect the confidentiality, integrity, and availability (CIA) of their
information. These three elements form the basis good information security.
ISO 27001 helps protect information in any form, but cybersecurity—which protects digital
information—plays a major role.
Kildow Consulting
Cyber
Security vs
Information
Security
* Definition by the National Institute of Standards and Technology (NIST)
** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
Kildow Consulting
Cyber
Security vs
Information
Security
* Definition by the National Institute of Standards and Technology (NIST)
** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
Kildow Consulting
Cyber
Security vs
Information
Security
* Definition by the National Institute of Standards and Technology (NIST)
** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
Kildow Consulting
Cyber
Security vs
Information
Security
* Definition by the National Institute of Standards and Technology (NIST)
** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
Kildow Consulting
• A technical topic well explained in “laymen’s terms”
• Generic – 2013 version!
• Helpful as a starting point in order to measure/benchmark your IS maturity
• Good outline of Information Security controls (Annex A)
• Well aligned with other standards and guidelines (e.g. ISO 22301, ISO 31000, SOC2,
NIST etc)
• Various related guidelines for further support (e.g. ISO 27002 – IS controls, ISO 27032 -
Cyber Risk, ISO 27017 – Cloud services, ISO 27018 – Personally Identifiable Information
in public Clouds, ISO 28000 – Supply Chain Security)
• Note: ISO 27001 goes beyond electronic information security.
ISO 27001 - Will it break or make your process?
Kildow Consulting
ISO/IEC 27001:2013 – Security Controls (Annex A)
Kildow Consulting
ISO/IEC 27001 provides requirements for organizations that are seeking to establish,
implement, maintain, and continually improve an information security management system.
As such, organisations can get certified against it.
ISO/IEC 27002 is an international standard used as a reference for selecting and
implementing information security controls listed in Annex A of ISO/IEC 27001. It is used as
guidance on the best practices of information security management helping organisations in
selecting, implementing, and managing the controls of ISO/IEC 27001. Organisations
cannot get a certification against ISO/IEC 27002. It serves as supporting material in
implementing the requirements.
What is the difference between ISO/IEC 27001 & ISO/IEC 27002?
Kildow Consulting
Number of controls
The revised version of ISO/IEC 27002 published in 2022 decreases the number of
information security controls from 114 controls to 93 controls, covered in four sections:
• Organizational controls (clause 5)
• People controls (clause 6)
• Physical controls (clause 7)
• Technological controls (clause 8)
What are the main changes in ISO/IEC 27002:2022?
Kildow Consulting
New controls
The ISO/IEC 27002:2022 introduced 11 new controls, as stated in the following:
• 5.7 Threat intelligence
• 5.23 Information security for use of cloud services
• 5.30 ICT readiness for business continuity
• 7.4 Physical security monitoring
• 8.9 Configuration management
• 8.10 Information deletion
• 8.11 Data masking
• 8.12 Data leakage prevention
• 8.16 Monitoring activities
• 8.23 Web filtering
• 8.28 Secure coding
What are the main changes in ISO/IEC 27002:2022?
Kildow Consulting
Restructuring and merging of sections
• Despite the number of controls being reduced, no controls were excluded in the latest version
of the standard; however, they were merged.
• It is considered that based on the newest structure, the process of designation of
responsibilities and the applicability of controls will be easier.
How is ISO/IEC 27002:2022 impacting ISO/IEC 27001?
• There will be an amendment to ISO/IEC 27001:2013 (referred to as ISO/IEC
27001:2013+A1:2022).
• As such, the latest changes in ISO/IEC 27002:2022 will be reflected in Annex A of ISO/IEC
27001 with a normative version of the 93 new controls.
What are the main changes in ISO/IEC 27002:2022?
Kildow Consulting
Once the updated Annex A of ISO/IEC 27001 is published, you will need to update the
Statement of Applicability so it can be aligned with the new list of security controls.
Will the changes affect my organisation’s ISO/IEC 27001 certification?
• If you’re currently certified to ISO 27001:2013, you will need to make the transition to
ISO 27001:2022 before your first surveillance or recertification audit of 2023.
• Depending on the scope of your ISMS, you could be required to implement up to 11
new controls.
• Before your audit, those controls need to be put in place, enforced with policies and
procedures, and tested.
When should we start implementing the latest changes?
Kildow Consulting
….
Kildow Consulting
Risk Management & ISO 31000
Implementing a Risk
Management Framework Based
on ISO 31000
Kildow Consulting
Blockchain
Pandemics Cybersecurity
Climate Change
Artificial Intelligence Big Data
Our World Today
Kildow Consulting
Scope of ISO 31000
 Provides principles, a framework and
process for managing risks.
 It is easily adaptable to any business
regardless of sector or industry
 It is applicable to any type of risk – Including
Information Security and Business
Continuity Risks
 Aims to simplify risk management.
 Not intended for certification
Kildow Consulting
What is Risk and Risk Management?
Risk management refers to a coordinated
set of activities and methods that is used
to direct an organization and to control the
many risks that can affect its ability to
achieve objectives
According to ISO 31000, risk is the “effect
of uncertainty on objectives” and an effect is
a positive or negative deviation from what is
expected.
Kildow Consulting
Principles of Risk Management
The principles guide the establishment of the risk framework
Kildow Consulting
Risk Management Framework
 A risk management framework
provides the policies, procedures
and organizational arrangements
that will embed risk management
throughout the organization at all
levels.
 The framework guides the
establishment of the risk process.
Kildow Consulting
Risk Management Process
Kildow Consulting
Risk Assessment
Provides a structured process that identifies how objectives may
be affected and analyses the risk in terms of consequences and
their probabilities before deciding on whether further action is
required.
Risk Assessment attempts to answer the following fundamental
questions:
 What can happen and why? (By risk identification)
 What are the consequences?
 What is the probability of their future occurrence?
 Are there any factors that mitigate the consequence or
probability of the risk
 Is the level of risk tolerable or acceptable and does it require
further action
Kildow Consulting
Benefits of Effective Risk Management
 Organisations exhibiting mature risk
management practices outperform their
peers financially
 Enhanced compliance to legal and
contractual obligations
 Provides better quality data for decision
making
 Provides a roadmap for prioritizing actions
 Business Process Improvement
 Enhances communication and
collaboration within an organisation
Kildow Consulting
Considerations To Make
 What are our risk management objectives: What are we hoping to achieve with the
implementation of a risk framework based on ISO 31000
 Who is doing what: Roles and responsibilities should be clearly defined. Leadership must
support Risk Management. Everyone is a risk manager (In their roles, not necessarily in
title)
 How will it be implemented: Document a process tailored for the organisation.
 When will it be implemented: Risk management is a journey, not a destination. Risks
should be continually assessed and mitigation strategies re-considered. Change is
inevitable. Recognise new risks and opportunities.
Kildow Consulting
Continuous Improvement
This is a process of increasing the effectiveness
and efficiency of the organisation to fulfil its
policy and objectives
Taking consistent steps forward
Kildow Consulting
Discussion
Discussion Question
I understand how these three standards can be of value to my
company. We have not yet implemented any of these standards.
Where should we start?
Kildow Consulting
About ISO Standards
 ISO is a network of national
standardization bodies from over
160 countries
 There are more than 788
technical bodies for standard
development
 The final results of ISO works
are published as international
standards
 More than 21,000 standards
have been published since 1947
Facts
• We have choices
• All three standards have merit and value
• We can have basic knowledge and an understanding of all
three
• It is difficult to fully be a subject matter expert in everything
• An organization can be certified in multiple ISO standards
• But where to start?
Considerations
• Which of the three has greatest value to the organization and
its stakeholders today? In the future?
• Which aligns with the organization’s vision, mission, policies?
• Not the latest trend, one that it is the latest hot topic, or was a perfect
for another organization
• Is there a standard that is preferred or recommended by your
business sector, industry, or profession?
Making the Best Selection
• What other standards does your organization use?
• Have you read and understand the standard(s) you are considering?
• Which standard addresses the company’s current greatest risks?
• Which standard has buy-in from interested parties – including
executive management, business partners, regulatory agencies, etc.?
• Do a great many of your customers use, prefer, or require a specific
standard?
• Is there a standard that is more widely used in your industry?
• Are all the right people involved in the selection process?
Kildow Consulting
Discussion question:
How to minimise the ‘standards’ burden for staff?
Kildow Consulting
• Combine workshops where you can
• Create a ‘cross-walk’ of any standards and show the Sections in other standards that
cover the same/similar topics e.g. ISI 27001, NIST,
Key points to prevent ‘standards fatigue’
Kildow Consulting
BCP vs Cyber
Incident
Response
Planning:
Causes
Kildow Consulting
BCP vs Cyber
Incident
Response
Planning:
Consequences
Kildow Consulting
Organisation
02
Competence 01
Relationships
03
Motivation 04
Risk
culture
• Knowledge
• Skills
• Recruitment and
Induction
• Strategy and
Objectives
• Governance
• Values and Ethics
• Incentives
• Accountability
• Performance
Management
• Leadership
• Communication
Discussion Question:
How to Build a Culture in Your Organisation
Kildow Consulting
THANK YOU
bettykildow@gmail.com Betty Kildow
michaelkamau2013@gmail.com Michael Kamau Kiiru
rinskeg@businessasusual.com.au Rinske Geerlings

More Related Content

Similar to ISO/IEC 27001 vs ISO 22301 vs ISO 31000: What you need to know

ISO 22301:2019 (Business Continuity Management Systems) Awareness Training
ISO 22301:2019 (Business Continuity Management Systems) Awareness TrainingISO 22301:2019 (Business Continuity Management Systems) Awareness Training
ISO 22301:2019 (Business Continuity Management Systems) Awareness TrainingOperational Excellence Consulting
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectContinuity and Resilience
 
Iso 22301 2012 bcm
Iso 22301 2012 bcmIso 22301 2012 bcm
Iso 22301 2012 bcmfaisal_ss
 
NQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation GuideNQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation GuideNA Putra
 
ISO 9001 Foundation Training Course - Sample Slides
ISO 9001 Foundation Training Course - Sample SlidesISO 9001 Foundation Training Course - Sample Slides
ISO 9001 Foundation Training Course - Sample SlidesStratos Lazaridis
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectCORE Consulting
 
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT Continuity and Resilience
 
Business Continuity as a Career
Business Continuity as a CareerBusiness Continuity as a Career
Business Continuity as a CareerBonnie Canal
 
Qa & compliance manager advert
Qa & compliance manager advertQa & compliance manager advert
Qa & compliance manager advertMelanie Tellwright
 
ISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfZoyaAbdul1
 
A Compact guide of ISO certification with quality process manual
A Compact guide of ISO certification with quality process manualA Compact guide of ISO certification with quality process manual
A Compact guide of ISO certification with quality process manualEstartupindia.com
 
Verde your sustainability partner for business growth
Verde   your sustainability partner for business growthVerde   your sustainability partner for business growth
Verde your sustainability partner for business growthVerde Ventures Pvt. Ltd.
 
KEVIN ALBERT JOYCE PROPOSAL (1).pdf
KEVIN ALBERT JOYCE  PROPOSAL (1).pdfKEVIN ALBERT JOYCE  PROPOSAL (1).pdf
KEVIN ALBERT JOYCE PROPOSAL (1).pdfQMSCATPRIVATE
 
The Nuts & Bolts of ISO 9001
The Nuts & Bolts of ISO 9001The Nuts & Bolts of ISO 9001
The Nuts & Bolts of ISO 9001BSI America
 
Business Responsibility Reporting
Business Responsibility ReportingBusiness Responsibility Reporting
Business Responsibility ReportingRSM GC
 
Fbh talk version_final vf.pptx[42] - read-only
Fbh talk version_final vf.pptx[42]  -  read-onlyFbh talk version_final vf.pptx[42]  -  read-only
Fbh talk version_final vf.pptx[42] - read-onlyForBetterHealthForBe
 
ISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationQualsys Ltd
 
Caw Certification Services - Company Information
Caw Certification Services - Company InformationCaw Certification Services - Company Information
Caw Certification Services - Company InformationCraig Willetts ISO Expert
 

Similar to ISO/IEC 27001 vs ISO 22301 vs ISO 31000: What you need to know (20)

ISO 22301:2019 (Business Continuity Management Systems) Awareness Training
ISO 22301:2019 (Business Continuity Management Systems) Awareness TrainingISO 22301:2019 (Business Continuity Management Systems) Awareness Training
ISO 22301:2019 (Business Continuity Management Systems) Awareness Training
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR Project
 
Mahalakshmi_Profile
Mahalakshmi_ProfileMahalakshmi_Profile
Mahalakshmi_Profile
 
Iso 22301 2012 bcm
Iso 22301 2012 bcmIso 22301 2012 bcm
Iso 22301 2012 bcm
 
NQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation GuideNQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation Guide
 
LRQA ISO Standards Update - Integration as Standard? October 2013
LRQA ISO Standards Update - Integration as Standard?   October 2013LRQA ISO Standards Update - Integration as Standard?   October 2013
LRQA ISO Standards Update - Integration as Standard? October 2013
 
ISO 9001 Foundation Training Course - Sample Slides
ISO 9001 Foundation Training Course - Sample SlidesISO 9001 Foundation Training Course - Sample Slides
ISO 9001 Foundation Training Course - Sample Slides
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR project
 
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
 
Business Continuity as a Career
Business Continuity as a CareerBusiness Continuity as a Career
Business Continuity as a Career
 
Qa & compliance manager advert
Qa & compliance manager advertQa & compliance manager advert
Qa & compliance manager advert
 
ISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdf
 
A Compact guide of ISO certification with quality process manual
A Compact guide of ISO certification with quality process manualA Compact guide of ISO certification with quality process manual
A Compact guide of ISO certification with quality process manual
 
Verde your sustainability partner for business growth
Verde   your sustainability partner for business growthVerde   your sustainability partner for business growth
Verde your sustainability partner for business growth
 
KEVIN ALBERT JOYCE PROPOSAL (1).pdf
KEVIN ALBERT JOYCE  PROPOSAL (1).pdfKEVIN ALBERT JOYCE  PROPOSAL (1).pdf
KEVIN ALBERT JOYCE PROPOSAL (1).pdf
 
The Nuts & Bolts of ISO 9001
The Nuts & Bolts of ISO 9001The Nuts & Bolts of ISO 9001
The Nuts & Bolts of ISO 9001
 
Business Responsibility Reporting
Business Responsibility ReportingBusiness Responsibility Reporting
Business Responsibility Reporting
 
Fbh talk version_final vf.pptx[42] - read-only
Fbh talk version_final vf.pptx[42]  -  read-onlyFbh talk version_final vf.pptx[42]  -  read-only
Fbh talk version_final vf.pptx[42] - read-only
 
ISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentation
 
Caw Certification Services - Company Information
Caw Certification Services - Company InformationCaw Certification Services - Company Information
Caw Certification Services - Company Information
 

More from PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 

More from PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Recently uploaded

SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application ) Sakshi Ghasle
 
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Celine George
 
Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17Celine George
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsKarinaGenton
 
Final demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxFinal demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxAvyJaneVismanos
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTiammrhaywood
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...Marc Dusseiller Dusjagr
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxmanuelaromero2013
 
Blooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docxBlooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docxUnboundStockton
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,Virag Sontakke
 
How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17Celine George
 
Pharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfPharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfMahmoud M. Sallam
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaVirag Sontakke
 
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting DataJhengPantaleon
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 

Recently uploaded (20)

TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdfTataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application )
 
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
 
Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its Characteristics
 
Final demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxFinal demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptx
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
 
Staff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSDStaff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSD
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptx
 
Blooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docxBlooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docx
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
 
How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17
 
Pharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfPharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdf
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of India
 
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 

ISO/IEC 27001 vs ISO 22301 vs ISO 31000: What you need to know

  • 2. Kildow Consulting  Business continuity and supply chain management consultant, advisor, trainer, speaker, author  More than 25 years partnering with widely diverse businesses and organizations to develop and maintain continuity and resilience  Fellow of the Business Continuity Institute (FBCI) 2002  Certified Business Continuity Professional (CBCP), DRII 1998  ISO 22301 Master  ISO 28000 Lead Implementer/Lead Auditor  Conduct ISO-28000 and ISO-22301 internal audits and reviews  PECB Certified Trainer  Author, A Supply Chain Management Guide to Business Continuity, 2011; in Japanese「事業継続」のためのサプライチェーン・マネジメント Betty A. Kildow
  • 3. Kildow Consulting • Founder & Principal Consultant @ Business As Usual (started 2006) • MSc (Engineering) – TU Delft, the Netherlands - Honours • 20+ years of consulting experience globally • ISO 22301 Master – ISO 31000 Lead Risk Mgr – ISO 27001 Master • CBCP, MBCI, ITIL Master, COBIT certified • Regularly conducting ISO 27001 certification audits • Consulted to 15 Central Banks and 100s of other Government entities, SMEs and larger corporates across Australasia, Africa, Europe and Latin America Rinske Geerlings Risk Consultant of the Year 2017 (RMIA) Outstanding Security Consultant of the Year 2019 (OSPAs Finalist)
  • 4. Kildow Consulting • ISO 31000 Lead Risk Manager • ISO 22301 Lead Implementer • ISO 9001 Lead Implementer • PECB Certified Trainer • Worked with clients across industries to develop and review their enterprise risk and business continuity management frameworks. Michael Kamau Kiiru Senior Consultant at Sentinel Africa Consulting Experienced risk manager and trainer specializing in enterprise risk management, business continuity management Photo
  • 5. Kildow Consulting Business Continuity & ISO 22301 Essential in Building a More Resilient Organization
  • 6. Kildow Consulting What Is Business Continuity? 1,000,000 choices • Timely, orderly continuation or rapid restoration of delivery of the organization’s service or product following a disruption of any magnitude. • Includes strategies and plans developed from the perspective of keeping the most critical functions running while normal operations are restored. • Capability of the organization to continue delivery of products or services at acceptable predefined levels following a disruptive incident. ISO 22301, clause 3.3
  • 7. Kildow Consulting Here is Your First Quiz What is the precise full official name of ISO-22301 – with all correct punctuation?
  • 8. Kildow Consulting What is ISO 22301? • Full name of the standard is: ISO 22301:2019 Societal security – Business continuity management systems – Requirements. • Billed as the world's first international standard for business continuity management (BCM) – Written by leading business continuity experts – Provides the best framework for managing business continuity in an organization. • An organization can become certified by an accredited certification body and will therefore be able to prove its compliance to its customers, partners, owners and other stakeholders. • Any organization – large or small, for profit or non-profit, private or public can implement the standard. What is ISO 22301?
  • 9. Kildow Consulting ISO 22301 Standard Specifies requirements for BCMS management Requirements (clauses) are written using the imperative verb “shall” Integrate the PDCA (Plan, Do, Check and Act) model Auditable Organization can obtain certification against this standard
  • 10. Kildow Consulting Why ISO-22301:2012 Had Me at Hello Business Continuity Management System – Includes the supply chain – Requires top management involvement – Globally accepted standard – Sets requirements for a business continuity management system – Provides guidance on the implementation of a comprehensive Business Continuity Program – Provides solid evidence of business continuity competence Published in May 2012 by the technical committee, ISO 22301:2012 is the first international standard for management systems that help ensure business continuity. ISO 22301 is the premium standard for business continuity, and certification demonstrates conformance to rigorous practices to prevent, mitigate, respond to, and recover from disruptive incidents.
  • 11. Kildow Consulting Value of a Business Continuity Management System Many stakeholders care about your business continuity capability; some have a vested interest. In extreme situations the success, even survival, of your organization as it exists today may depend on its business continuity capability. The number of regulatory and legal requirements that include having a business continuity program continue to increase in number. For public utilities there is an ethical requirement to protect the interests of all customers. Customers need and expect your products and services to be available even when significant disruptions and disasters occur. Developing, implementing, and maintaining a continuity program that ensures the organization can continue operations even in the face of disaster, thus avoiding damage to the company’s brand, image, and reputation, and losses to the bottom line.
  • 12. Kildow Consulting Advantages of Business Continuity Predictable and effective response to crises Protection of people Maintenance of vital activities of the organization Better understanding of the organization Mitigation of Risks Respect of the interested parties Protection of the reputation and brand Confidence of clients Competitive advantage Legal compliance Regulatory compliance Contract compliance
  • 13. Kildow Consulting Definition: Establishment of policies and continuous monitoring of their proper implementation by members of the governing body of an organization • Adopt formal Business Continuity Policy • Identify who has overall ownership • Establish a central point of accountability, oversight, and support • Ensure proper monitoring to ensure requirements are met - and follow-up as necessary • Assign roles and responsibilities
  • 14. Kildow Consulting Business Continuity’s Value Beyond Business Continuity • Gather information from across the organization • Gain an in-depth understanding of the big picture • Develop a greater understanding of internal and external interdependencies • Identify redundancies and opportunities for efficiencies
  • 15. Kildow Consulting “You can't go back and change the beginning, but you can start where you are and change the ending.” C.S.Lewis COVID – Two Years and Counting  Global  Prolonged  Impacted people, facilities, equipment, suppliers, technology, infrastructure  Required extraordinary levels of adaptability  What seemed impossible was made possible  Higher awareness of the need for business continuity than ever before  Unparalleled lessons for needed improvements to our Business Continuity Programs
  • 16. Kildow Consulting Requirements for Successful Business Continuity Enterprise-wide integrated involvement Total collaboration among all risk- related business units Fully addressing a wide range of internal and external operational risks Strategies and plans that are flexible, scalable
  • 17. Kildow Consulting Internal Partnering Strategy and plan development • Give ownership to the implementers • Train and empower IT/DR • Collaborative DR and BC exercises and tests • IT is also a business unit One small step for business continuity- kind; one giant step for a successful BCMS • Adopt a shared glossary of business continuity terms and acronyms that is used across the organization
  • 18. Kildow Consulting • Business Continuity Plans need to outline how each individual plan coordinates, collaborates, and communicates with other plans: – Corporate-level Business Continuity Plan – Department / Division Business Continuity Plans at all locations – Business Continuity Plans for strategic, tactical and operational levels – Disaster Recovery Plan – Emergency Response Plan – Other risk-related plans • A change in one will likely require changes in others
  • 19. Kildow Consulting Business Continuity’s Role in Cybersecurity and Vice Versa • It is a fact that BC, DR and Cybersecurity activities often occupy separate silos • Those barriers need to come down • Business continuity does not prevent nor lead the charge to recover from cyber attacks • Business Continuity’s role is to ensure that the organization can still function in spite of any disruption, including of cyber attacks Collaboration is the key to success. There is strength and power in coming together to find answers to current and future common challenges.
  • 20. Kildow Consulting Executive sponsorship, involvement, and commitment Focus on sustaining operations essential to the delivery of products and services Clearly defined ownership and responsibility Full communication of the program enterprise wide Full coordination and integration of all risk-related programs Regular reviews and audits and updates Comprehensive training, exercising and testing Integrated into culture and operations ISO-22301 Essentials for Ongoing Business Continuity Success
  • 21. Kildow Consulting Information Security & ISO 27001 Recent ISO 27001 developments & Differences between Cyber Incident Response Planning and ISMS
  • 22. Kildow Consulting Why ISMS? Compliance (SOC, Sox, 3rd party)
  • 24. Kildow Consulting Ransom payments… IN PRINCIPLE ≠ IN PRACTICE
  • 25. Kildow Consulting ISO 27001 – What is it? ISO/IEC 27001 (usually shortened to “ISO 27001”) is an Information Security Management System standard written jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (EC). This standard lays out universal best practices for creating and maintaining an information security management system (ISMS). It helps organizations protect the confidentiality, integrity, and availability (CIA) of their information. These three elements form the basis good information security. ISO 27001 helps protect information in any form, but cybersecurity—which protects digital information—plays a major role.
  • 26. Kildow Consulting Cyber Security vs Information Security * Definition by the National Institute of Standards and Technology (NIST) ** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
  • 27. Kildow Consulting Cyber Security vs Information Security * Definition by the National Institute of Standards and Technology (NIST) ** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
  • 28. Kildow Consulting Cyber Security vs Information Security * Definition by the National Institute of Standards and Technology (NIST) ** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
  • 29. Kildow Consulting Cyber Security vs Information Security * Definition by the National Institute of Standards and Technology (NIST) ** Combining elements from ISO 27035, ISO 27032 and ISO 27001 and NIST 800-61
  • 30. Kildow Consulting • A technical topic well explained in “laymen’s terms” • Generic – 2013 version! • Helpful as a starting point in order to measure/benchmark your IS maturity • Good outline of Information Security controls (Annex A) • Well aligned with other standards and guidelines (e.g. ISO 22301, ISO 31000, SOC2, NIST etc) • Various related guidelines for further support (e.g. ISO 27002 – IS controls, ISO 27032 - Cyber Risk, ISO 27017 – Cloud services, ISO 27018 – Personally Identifiable Information in public Clouds, ISO 28000 – Supply Chain Security) • Note: ISO 27001 goes beyond electronic information security. ISO 27001 - Will it break or make your process?
  • 31. Kildow Consulting ISO/IEC 27001:2013 – Security Controls (Annex A)
  • 32. Kildow Consulting ISO/IEC 27001 provides requirements for organizations that are seeking to establish, implement, maintain, and continually improve an information security management system. As such, organisations can get certified against it. ISO/IEC 27002 is an international standard used as a reference for selecting and implementing information security controls listed in Annex A of ISO/IEC 27001. It is used as guidance on the best practices of information security management helping organisations in selecting, implementing, and managing the controls of ISO/IEC 27001. Organisations cannot get a certification against ISO/IEC 27002. It serves as supporting material in implementing the requirements. What is the difference between ISO/IEC 27001 & ISO/IEC 27002?
  • 33. Kildow Consulting Number of controls The revised version of ISO/IEC 27002 published in 2022 decreases the number of information security controls from 114 controls to 93 controls, covered in four sections: • Organizational controls (clause 5) • People controls (clause 6) • Physical controls (clause 7) • Technological controls (clause 8) What are the main changes in ISO/IEC 27002:2022?
  • 34. Kildow Consulting New controls The ISO/IEC 27002:2022 introduced 11 new controls, as stated in the following: • 5.7 Threat intelligence • 5.23 Information security for use of cloud services • 5.30 ICT readiness for business continuity • 7.4 Physical security monitoring • 8.9 Configuration management • 8.10 Information deletion • 8.11 Data masking • 8.12 Data leakage prevention • 8.16 Monitoring activities • 8.23 Web filtering • 8.28 Secure coding What are the main changes in ISO/IEC 27002:2022?
  • 35. Kildow Consulting Restructuring and merging of sections • Despite the number of controls being reduced, no controls were excluded in the latest version of the standard; however, they were merged. • It is considered that based on the newest structure, the process of designation of responsibilities and the applicability of controls will be easier. How is ISO/IEC 27002:2022 impacting ISO/IEC 27001? • There will be an amendment to ISO/IEC 27001:2013 (referred to as ISO/IEC 27001:2013+A1:2022). • As such, the latest changes in ISO/IEC 27002:2022 will be reflected in Annex A of ISO/IEC 27001 with a normative version of the 93 new controls. What are the main changes in ISO/IEC 27002:2022?
  • 36. Kildow Consulting Once the updated Annex A of ISO/IEC 27001 is published, you will need to update the Statement of Applicability so it can be aligned with the new list of security controls. Will the changes affect my organisation’s ISO/IEC 27001 certification? • If you’re currently certified to ISO 27001:2013, you will need to make the transition to ISO 27001:2022 before your first surveillance or recertification audit of 2023. • Depending on the scope of your ISMS, you could be required to implement up to 11 new controls. • Before your audit, those controls need to be put in place, enforced with policies and procedures, and tested. When should we start implementing the latest changes?
  • 38. Kildow Consulting Risk Management & ISO 31000 Implementing a Risk Management Framework Based on ISO 31000
  • 39. Kildow Consulting Blockchain Pandemics Cybersecurity Climate Change Artificial Intelligence Big Data Our World Today
  • 40. Kildow Consulting Scope of ISO 31000  Provides principles, a framework and process for managing risks.  It is easily adaptable to any business regardless of sector or industry  It is applicable to any type of risk – Including Information Security and Business Continuity Risks  Aims to simplify risk management.  Not intended for certification
  • 41. Kildow Consulting What is Risk and Risk Management? Risk management refers to a coordinated set of activities and methods that is used to direct an organization and to control the many risks that can affect its ability to achieve objectives According to ISO 31000, risk is the “effect of uncertainty on objectives” and an effect is a positive or negative deviation from what is expected.
  • 42. Kildow Consulting Principles of Risk Management The principles guide the establishment of the risk framework
  • 43. Kildow Consulting Risk Management Framework  A risk management framework provides the policies, procedures and organizational arrangements that will embed risk management throughout the organization at all levels.  The framework guides the establishment of the risk process.
  • 45. Kildow Consulting Risk Assessment Provides a structured process that identifies how objectives may be affected and analyses the risk in terms of consequences and their probabilities before deciding on whether further action is required. Risk Assessment attempts to answer the following fundamental questions:  What can happen and why? (By risk identification)  What are the consequences?  What is the probability of their future occurrence?  Are there any factors that mitigate the consequence or probability of the risk  Is the level of risk tolerable or acceptable and does it require further action
  • 46. Kildow Consulting Benefits of Effective Risk Management  Organisations exhibiting mature risk management practices outperform their peers financially  Enhanced compliance to legal and contractual obligations  Provides better quality data for decision making  Provides a roadmap for prioritizing actions  Business Process Improvement  Enhances communication and collaboration within an organisation
  • 47. Kildow Consulting Considerations To Make  What are our risk management objectives: What are we hoping to achieve with the implementation of a risk framework based on ISO 31000  Who is doing what: Roles and responsibilities should be clearly defined. Leadership must support Risk Management. Everyone is a risk manager (In their roles, not necessarily in title)  How will it be implemented: Document a process tailored for the organisation.  When will it be implemented: Risk management is a journey, not a destination. Risks should be continually assessed and mitigation strategies re-considered. Change is inevitable. Recognise new risks and opportunities.
  • 48. Kildow Consulting Continuous Improvement This is a process of increasing the effectiveness and efficiency of the organisation to fulfil its policy and objectives Taking consistent steps forward
  • 50. Discussion Question I understand how these three standards can be of value to my company. We have not yet implemented any of these standards. Where should we start?
  • 51. Kildow Consulting About ISO Standards  ISO is a network of national standardization bodies from over 160 countries  There are more than 788 technical bodies for standard development  The final results of ISO works are published as international standards  More than 21,000 standards have been published since 1947
  • 52. Facts • We have choices • All three standards have merit and value • We can have basic knowledge and an understanding of all three • It is difficult to fully be a subject matter expert in everything • An organization can be certified in multiple ISO standards • But where to start?
  • 53. Considerations • Which of the three has greatest value to the organization and its stakeholders today? In the future? • Which aligns with the organization’s vision, mission, policies? • Not the latest trend, one that it is the latest hot topic, or was a perfect for another organization • Is there a standard that is preferred or recommended by your business sector, industry, or profession?
  • 54. Making the Best Selection • What other standards does your organization use? • Have you read and understand the standard(s) you are considering? • Which standard addresses the company’s current greatest risks? • Which standard has buy-in from interested parties – including executive management, business partners, regulatory agencies, etc.? • Do a great many of your customers use, prefer, or require a specific standard? • Is there a standard that is more widely used in your industry? • Are all the right people involved in the selection process?
  • 55. Kildow Consulting Discussion question: How to minimise the ‘standards’ burden for staff?
  • 56. Kildow Consulting • Combine workshops where you can • Create a ‘cross-walk’ of any standards and show the Sections in other standards that cover the same/similar topics e.g. ISI 27001, NIST, Key points to prevent ‘standards fatigue’
  • 57. Kildow Consulting BCP vs Cyber Incident Response Planning: Causes
  • 58. Kildow Consulting BCP vs Cyber Incident Response Planning: Consequences
  • 59. Kildow Consulting Organisation 02 Competence 01 Relationships 03 Motivation 04 Risk culture • Knowledge • Skills • Recruitment and Induction • Strategy and Objectives • Governance • Values and Ethics • Incentives • Accountability • Performance Management • Leadership • Communication Discussion Question: How to Build a Culture in Your Organisation
  • 60. Kildow Consulting THANK YOU bettykildow@gmail.com Betty Kildow michaelkamau2013@gmail.com Michael Kamau Kiiru rinskeg@businessasusual.com.au Rinske Geerlings